[RC5] Win98

gindrup at okway.okstate.edu gindrup at okway.okstate.edu
Wed Jul 1 16:08:18 EDT 1998


     Warning!  Win98 is vastly insecure.  The following trivial attack will 
     cause you great grief:
     
     1) If you have file/printer sharing enabled (not actually sharing 
     anything, just have the option enabled), your desktop is writable by 
     the world.
     2) Since the desktop is an HTML document, it can contain ActiveX 
     controls.
     3) Local ActiveX code is not AuthentiCoded, so you will not be asked 
     whether you want to accept an unsigned ActiveX control if it is on 
     your desktop.
     4) Any attacker can install such a control on your Desktop.
     5) Using:
     http://www.cs.auckland.ac.nz/~pgut001/pubs/pwl.txt
        and
     http://www.geek-girl.com/bugtraq/1995_4/0138.html
        use your machine to hack your password (if you have one).
     6) Do any other malicious thing it wants.
     7) Add an item to the restart queue ("Setup is changing your 
     Configuration Files...") to delete itself.
     
     I'm not advocating against Win98.  Just remember, if you're using it, 
     your probably "flying exposed" and there is very little you can do 
     about it.
     
     As for the links above: I think this is more than ample reason to 
     *not* like IE bundled in any OS.
            -- Eric Gindrup ! gindrup at okway.okstate.edu


______________________________ Reply Separator _________________________________
Subject: [RC5] Win98 
Author:  <rc5 at lists.distributed.net> at SMTP
Date:    1998/06/30 22:25


I recently upgraded to win98 and I found that my average keys/sec went up from u
ally being around 820,000 - 800,000 to around 820,000 - 840,000. Is that common 
r all who upgrade to win98 from win95?
     
Lars


--
To unsubscribe, send 'unsubscribe rc5' to majordomo at lists.distributed.net
rc5-digest subscribers replace rc5 with rc5-digest



More information about the rc5 mailing list